Executive brief
OpenCart, a popular open-source e-commerce platform, is vulnerable to a session hijacking flaw. An attacker can force a specific session identifier on a user, allowing the attacker to take over the user's account once they log in. This could lead to unauthorized access to customer personal information, order history, and administrative functions.
Technical details
A session fixation vulnerability exists in OpenCart version 3.0.3.8 due to improper processing of the OCSESSID cookie. The application fails to invalidate or regenerate session identifiers upon authentication and accepts arbitrary session IDs provided by the client. A remote, unauthenticated attacker can set a known OCSESSID value in a victim's browser; once the victim authenticates, the attacker can use the fixed session ID to bypass authentication and gain full access to the victim's session. This is classified as CWE-290 (Authentication Bypass by Spoofing) and can be exploited over the network without user interaction beyond the victim's normal login process.
Affected products
- OpenCart OpenCart 3.0.3.8
Timeline
- 2021-11-28: other: Vulnerability discovered and exploit code authored
- 2021-11-29: disclosed: Exploit published on Exploit-DB
- 2026-05-10: advisory: CVE published/updated in NVD via VulnCheck